Skip to content
aicoolies logo
FuzzyAI logo

FuzzyAI

CyberArk's open-source LLM fuzzing framework for AI security testing

FuzzyAI is CyberArk's Apache-2.0 framework for fuzzing LLM APIs to identify jailbreaks and related security vulnerabilities. Current README examples cover Ollama/local models, OpenAI, Anthropic, custom REST endpoints, and attacks such as ManyShot, Taxonomy, and ArtPrompt. Use it as a repeatable security-testing starting point, not a complete AI risk-management system.

About FuzzyAI

FuzzyAI applies fuzz-testing ideas to large language model APIs by running documented attack examples against configured model targets. Developed by CyberArk's security research team, the Apache-2.0 project currently documents jailbreak-oriented fuzzing plus examples for ManyShot, Taxonomy, and ArtPrompt-style attacks across OpenAI, Anthropic, Ollama/local models, and custom REST APIs.

The framework operates against documented provider examples rather than a guaranteed universal model matrix: OpenAI, Anthropic, Ollama/local models, and custom REST API targets are visible in the current README. Teams that need governance-grade evidence should wrap the CLI output with their own severity taxonomy, storage, and remediation workflow. This evidence-based approach helps security teams quantify LLM risk rather than relying on qualitative assessments of model safety.

With 1.4K+ GitHub stars and CyberArk stewardship, FuzzyAI fills a useful gap for teams that want a repeatable starting point for LLM security testing without building every fuzzing prompt from scratch. The repository was active in the source check, but the latest push observed in this pass was 2026-02-06, so production users should review current issue activity and code paths before standardizing on it.

Pricing & Platform Specs

Pricing Summary

Free and 100% open-source under the Apache-2.0 license. CyberArk FuzzyAI has $0 software licensing fees and no paid subscription tiers. Testing runs under a Bring Your Own Key (BYOK) model or local inference setup, with operational costs strictly determined by underlying LLM API token consumption (OpenAI, Anthropic, Azure, Bedrock, Gemini) or local GPU/CPU compute (Ollama).

full pricing breakdown →

Supported Platforms

Python, any OS, tests any LLM via API

Explore categories, tags & use cases

Enterprise middleware for securing AI applications against prompt attacks

Prompt Security provides enterprise security middleware that protects AI applications from prompt injection, data leakage, jailbreaks, and toxic content generation. It sits between users and LLM APIs to inspect, filter, and sanitize inputs and outputs in real-time. Supports deployment as a proxy, SDK integration, or browser extension with customizable security policies and compliance reporting.

paid

Developer-first security platform

Snyk is the leading developer security platform providing continuous scanning for vulnerabilities in code (SAST), open-source dependencies (SCA), container images, and infrastructure as code. Integrates directly into IDEs, Git repositories, CI/CD pipelines, and container registries. Features AI-powered fix suggestions, license compliance checking, and real-time vulnerability database. Free for individual developers with paid plans for teams. Supports 30+ programming languages.

freemium

Community experience

Sources & verification

Sources checked
Content verified

Verification dates are editorial checks. Routine CMS saves and automatic updatedAt timestamps do not advance them.

FAQ

What is FuzzyAI?

FuzzyAI is CyberArk's Apache-2.0 framework for fuzzing LLM APIs to identify jailbreaks and related security vulnerabilities. Current README examples cover Ollama/local models, OpenAI, Anthropic, custom REST endpoints, and attacks such as ManyShot, Taxonomy, and ArtPrompt. Use it as a repeatable security-testing starting point, not a complete AI risk-management system.

Is FuzzyAI free?

Yes — FuzzyAI is open source and free to use. Free and 100% open-source under the Apache-2.0 license. CyberArk FuzzyAI has $0 software licensing fees and no paid subscription tiers. Testing runs under a Bring Your Own Key (BYOK) model or local inference setup, with operational costs strictly determined by underlying LLM API token consumption (OpenAI, Anthropic, Azure, Bedrock, Gemini) or local GPU/CPU compute (Ollama).

Is FuzzyAI open source?

Yes — FuzzyAI is open source.

Is FuzzyAI still maintained?

Yes — FuzzyAI is active. Its listing was last verified on September 6, 2026.

What are the best FuzzyAI alternatives?

The first editor-selected FuzzyAI alternatives are Prompt Security, Snyk.

How does FuzzyAI score in our review?

The published editorial review lists FuzzyAI at 82/100 overall across speed, privacy, and developer experience. Check the review's evidence status and test metadata for its verification level.